[ { "category": "Authentication", "description": "Single sign-on for Jellyfin via OpenID Connect and SAML 2.0 — works with self-hosted and\nmanaged identity providers such as Authelia, Authentik, Keycloak, Pocket ID and Kanidm,\nwith multiple providers side by side.\nRole-based access from provider claims (login, administrator, library folders, Live TV),\navatar sync, self-service account linking, and an optional SSO-only mode that disables\npassword login for every account except a designated break-glass admin.\nSign-in works in the Jellyfin Web UI and, via Quick Connect, in native clients.\nA security-first continuation of the archived 9p4/jellyfin-plugin-sso.\nDocumentation and provider setup guides: https://github.com/iderex/jellyfin-plugin-sso\n", "guid": "505ce9d1-d916-42fa-86ca-673ef241d7df", "imageUrl": "https://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/main/img/logo.png", "name": "SSO Authentication", "overview": "Sign in to Jellyfin through OpenID Connect or SAML 2.0 identity providers.", "owner": "iderex", "versions": [ { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.20).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Test config XML lifecycle round-trip (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/635\n* Test [Authorize]-policy enforcement end-to-end (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/636\n* Test fake-IdP OIDC challenge->callback->auth round-trip (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/637\n* Record the manual release-QA checklist (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/638\n* Explicit deny in AssertCanUpdateUser on a null auth context (#626) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/641\n* Fix .NET CI startup_failure on 4.2 (reusable build.yml permissions) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/643\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/5.0.0-JF12-beta.19...5.0.0-JF12-beta.20", "checksum": "b682d1d9e5f2c537d2f5ff33869de91a", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.20/sso-authentication_5.0.0.20.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-19T06:41:53Z", "version": "5.0.0.20" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.19).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Publish JF12 beta daily, not per 4.2 merge (#632) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/633\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/5.0.0-JF12-beta.18...5.0.0-JF12-beta.19", "checksum": "e775831b52973daf611381bcb0cac4a9", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.19/sso-authentication_5.0.0.19.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T22:39:42Z", "version": "5.0.0.19" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.18).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Test SSOViewsController GetView (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/630\n* Test FlowResponses shaping helpers (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/631\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/5.0.0-JF12-beta.16...5.0.0-JF12-beta.18", "checksum": "38df2a3de43916965d925b82db8dffc8", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.18/sso-authentication_5.0.0.18.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T22:22:16Z", "version": "5.0.0.18" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.16).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Test ProviderConfigValidator reject paths (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/629\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/5.0.0-JF12-beta.15...5.0.0-JF12-beta.16", "checksum": "97b8fd7cfd1cc0aabb8c651e6157b123", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.16/sso-authentication_5.0.0.16.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T22:20:40Z", "version": "5.0.0.16" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.15).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Forward-merge main into 4.2 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/562\n* Widen SourceFilesDeclaring to match record struct and struct declarations by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/558\n* Add SAML service-provider metadata endpoint by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/567\n* Forward-merge main into 4.2 (post-4.1.0.0 fixes) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/572\n* Add a SAML SP signing-key rollover (part 1 of #491) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/573\n* Forward-merge main into 4.2 (codeql.yml advanced setup) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/576\n* Add an admin Test-connection action per provider by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/577\n* Add admin config export/import (#161) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/581\n* Forward-merge main into 4.2 (README banner) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/580\n* Accept a SAML response signed by an optional secondary IdP certificate (completes #491) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/582\n* Forward-merge main into 4.2 (CA1873 log hygiene + Alpha docs) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/588\n* Forward-merge main into 4.2 (the 4.1.1.0 line + release channels) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/595\n* Multi-target net9.0/net10.0 for the 10.11 and 12.0 lines (#135) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/596\n* Forward-merge main into 4.2 (3-part versions + release naming) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/598\n* Evaluate SAML assertion roles once per login (#479) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/599\n* Scoped Stryker.NET mutation testing for the SAML/OIDC core (#169) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/600\n* Weekly SharpFuzz job over the SAML parse surface (#174) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/601\n* Forward-merge main into 4.2, set 4.2 to its 4.2.0 feature target by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/603\n* Collapse SamlChallenge relayState init to a ternary (#456) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/604\n* Jellyfin 12.0 (5.0) beta publish leg + two-channel manifest model (#135) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/605\n* Attest SLSA build provenance for the release plugin zip (#147) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/609\n* Drop the deprecated assertion-embedded SAML/Auth path (#528) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/610\n* Document the whole-object-replace contract on provider config (S6964, #196) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/615\n* Decompose ConvertSigningKeys to cut OIDC id_token validator complexity (S3776, #196) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/616\n* Accept-with-reason analyzer dispositions in .editorconfig (#104 Unit 0) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/617\n* Make WebResponse string ops culture-invariant (#104 Unit 1) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/618\n* Adopt System.Threading.Lock in three lock sites (#104 Unit 3) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/619\n* Add paramName to ArgumentException throws (#104 Unit 2, MA0015) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/620\n* Correct the stale target-direction section in ARCHITECTURE.md (#318) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/621\n* Test the write-only secret converter redaction contract (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/622\n* Test the AuthorizeStateBinding anti-forgery cookie (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/623\n* Test the SsoRateLimitGate 429 + fail-open invariant (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/624\n* Test the admin-or-self authorization helper (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/625\n* Anchor JF12 beta releases to the built 4.2 commit (#627) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/628\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.15", "checksum": "e336941292a6d18a44456cb3f4c975b9", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.15/sso-authentication_5.0.0.15.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T22:12:56Z", "version": "5.0.0.15" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.14).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.14", "checksum": "87b7f78766171dd296d38e4156ac6955", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.14/sso-authentication_5.0.0.14.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:57:21Z", "version": "5.0.0.14" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.13).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.13", "checksum": "ecc27cce3f224ecb9e50d0fbc460ab8c", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.13/sso-authentication_5.0.0.13.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:55:44Z", "version": "5.0.0.13" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.12).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.12", "checksum": "3f441c08ea392895974017fecb8af99b", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.12/sso-authentication_5.0.0.12.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:52:59Z", "version": "5.0.0.12" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.10).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.10", "checksum": "6ce9ab4404a03b0d783b763d78a2a57a", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.10/sso-authentication_5.0.0.10.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:51:34Z", "version": "5.0.0.10" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.9).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.9", "checksum": "0403588cbb598fb3a4e0c7cda1ce24b0", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.9/sso-authentication_5.0.0.9.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:44:21Z", "version": "5.0.0.9" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.8).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.8", "checksum": "4f2b50d3f90d03a118f8f7810991e2c0", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.8/sso-authentication_5.0.0.8.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:42:12Z", "version": "5.0.0.8" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.7).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.7", "checksum": "632123cebddf9533feeafc2f6b478096", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.7/sso-authentication_5.0.0.7.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:40:40Z", "version": "5.0.0.7" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.6).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.6", "checksum": "e3ac9c39c7b384b4c39971fed126e7f9", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.6/sso-authentication_5.0.0.6.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:38:34Z", "version": "5.0.0.6" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.5).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.5", "checksum": "a279d53a7f89e9af33eba8d60af07820", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.5/sso-authentication_5.0.0.5.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:31:01Z", "version": "5.0.0.5" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.4).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.4", "checksum": "e056bc6346e884134a33acff1ef0e4e8", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.4/sso-authentication_5.0.0.4.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:29:33Z", "version": "5.0.0.4" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.3).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.3", "checksum": "db56f4bbed7c112911955dda10f04b82", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.3/sso-authentication_5.0.0.3.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:15:50Z", "version": "5.0.0.3" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.2).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...5.0.0-JF12-beta.2", "checksum": "026d1070e6f898da97fcc5cb4810ea43", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.2/sso-authentication_5.0.0.2.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T21:05:08Z", "version": "5.0.0.2" }, { "changelog": "Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.1).\nInstall via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Beta tracks the next release target (4.1.2-beta), maintainer-set by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/602\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.1-beta.3...5.0.0-JF12-beta.1", "checksum": "6f45c46e999daad6826f0ef5098ecc89", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/5.0.0-JF12-beta.1/sso-authentication_5.0.0.1.zip", "targetAbi": "12.0.0.0", "timestamp": "2026-07-18T20:34:29Z", "version": "5.0.0.1" }, { "changelog": "Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.9).\nInstall via the beta repository URL:\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Link the ASVS/RFC 9700 conformance self-assessment from SECURITY by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/846\n* Enable deterministic build settings and document reproducibility by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/847\n* Route the OpenID discovery/JWKS/token fetches through the SSRF-hardened transport by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/848\n* Enforce a minimum asymmetric signing-key strength for IdP signing keys [#733] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/849\n* Provision new SSO users disabled pending admin approval [#737] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/850\n* Support step-up / MFA passthrough for OpenID [#757] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/851\n* Map IdP groups to a parental-rating ceiling (MaxParentalRatingScore) [#736] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/852\n* Show and copy the exact OIDC redirect URI on the provider form [#724] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/853\n* Import SAML provider config from IdP metadata (URL or XML) [#735] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/854\n* Add a SAML provider configuration admin UI [#725] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/855\n* Correct the actions/checkout pin comment to its exact tag [#858] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/859\n* Add one-click provider templates to the config page [#726] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/857\n* Auto-manage the login-page sign-in buttons (core) [#722] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/860\n* Add the Single Logout session-state store (SLO-1) [#727] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/861\n* Capture the id_token at login for Single Logout (SLO-1b) [#727] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/862\n* OIDC RP-initiated logout (SLO-2) [#727] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/863\n* Deduplicate the SAML metadata action doc; document two nested members by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/874\n* Add a shared TestUsers.Named factory; remove three copied user helpers by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/875\n* Finish the module placement: SSOViewsController + RequestHelpers into Http, dissolve the Kernel test folder by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/877\n* Collapse the two identical SAML signing-key resolvers into one helper by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/876\n* Delete the zero-consumer ILoginService interface by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/878\n* Consolidate served assets into one flat Web/ folder; add a resource-resolution test by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/879\n* Pin namespace to folder under Api/ with a conformance test by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/880\n* Document the internal API surface and enforce it via SA1600 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/881\n* Pin the internal-doc gate severities so it cannot be silently disabled by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/882\n* Point the repo docs at the consolidated wiki; fix module-table and beta-trigger drift by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/883\n* Add a CI wiki-lint drift guard by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/884\n* Record the OIDC/SAML shared-abstraction evaluation; codify the ≥2-consumer rule by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/885\n* Enable nullable reference types on the Flows module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/886\n* Enable nullable reference types on the LoginButtons module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/887\n* Bump System.Security.Cryptography.Xml to 10.0.10 (CVE-2026-47302, -47304) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/889\n* Enable nullable reference types on the Linking module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/891\n* Enable nullable reference types on the Logout module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/888\n* Enable nullable reference types on the Config module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/892\n* Enable nullable reference types on the Oidc module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/893\n* Enable nullable reference types on the Saml module (completes #799) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/894\n* Enable nullable reference types project-wide [#799] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/895\n* Generate and attach a CycloneDX SBOM to every release [#729] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/896\n* Adopt a DCO sign-off with a self-contained check [#746] by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/897\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.3.0-beta.8...4.3.0-beta.9", "checksum": "1e0d36e0b37af36898d9f81c0bf2aef8", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.3.0-beta.9/sso-authentication_4.3.0.9.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-21T06:37:54Z", "version": "4.3.0.9" }, { "changelog": "Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.8).\nInstall via the beta repository URL:\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* SSO-only login (DisablePasswordLogin) with a break-glass admin safety net (#165) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/665\n* Fail closed on a null FolderRoleMap.Folders in RolePrivilegeMapper by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/693\n* Key the OpenID authorize-state store on UTC, not machine-local time by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/696\n* Redesign the provider config page: workspace, chunked accordion, safe defaults by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/697\n* Harden SAML parsing: dispose the certificate, xsd-faithful time bounds, close XPath injection by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/698\n* Polish the served auth and self-service linking pages by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/701\n* Unify the challenge NewPath resolver and inline a single-caller OIDC wrapper by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/702\n* Correct the ProviderConfigValidator doc and tighten RequestHelpers visibility by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/703\n* Stop repointing third-party-provider accounts under SSO-only login by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/704\n* Type the rate-limit endpoint-class bucket keys by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/705\n* Audit SAML DoNotValidateAudience as an insecure toggle by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/706\n* Restyle browser-navigated SSO error responses and reword the denial by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/707\n* Advance the plugin to Beta for the 4.3.0 release by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/710\n* List SSO-only login in the README feature set by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/700\n* Add a docs/ pointer to the Wiki by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/711\n* Stop reflecting IdP error text into the OpenID browser error page by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/709\n* Show the real OpenSSF badges and a release badge in the README by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/770\n* Remove the orphaned img/custom-button.png asset by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/771\n* Bound the untrusted SAML DOM with MaxCharactersInDocument by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/772\n* Add a restrictive Permissions-Policy to the served auth and error pages by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/773\n* Clarify that this is an independent plugin repository, not the official catalog by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/774\n* Advertise both SAML ACS spellings in SP metadata by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/775\n* Fall back to the standard OIDC picture claim for avatars by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/776\n* Extract the Net module (networking/SSRF/URL primitives) into Api/Net by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/778\n* Extract the Secrets module (secrets at rest) into Api/Secrets by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/779\n* Extract the Audit module (audit logging) into Api/Audit by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/780\n* Extract the Avatar module (avatar fetch) into Api/Avatar by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/781\n* Extract the RateLimit module (login throttling) into Api/RateLimit by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/782\n* Remove the unused Nix dev-shell flake by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/783\n* Extract the Authz module (role to permission mapping) into Api/Authz by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/785\n* Extract the Provider module (config/test/naming) into Api/Provider by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/786\n* Extract the Linking module (account linking) into Api/Linking by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/787\n* Extract the Saml module (SAML core, validators, caches) into Api/Saml by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/788\n* Extract the Oidc module (OIDC flow, discovery, token) into Api/Oidc by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/789\n* Document the module architecture and the extension contract (docs/ARCHITECTURE.md) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/792\n* Mirror the source module structure in SSO-Auth.Tests (module test folders) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/793\n* Finish the SSO-Auth.Tests reorganisation + enforce the module-test mirror by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/794\n* Extract the shared ILoginService contract for OIDC and SAML by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/795\n* Invert VerifiedIdentity's dependency on the protocol modules by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/796\n* Extract the Identity module (VerifiedIdentity keystone) from the flat kernel by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/797\n* Extract the Session module (mint, outcomes, SSO-only) from the flat kernel by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/798\n* Move KeyedLockStore into the RateLimit module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/801\n* Split SsoUrlBuilder into per-protocol URL builders in their modules by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/802\n* Move the SAML library into the Saml module, one type per file (#800) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/803\n* Give the remaining root types their module homes by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/805\n* Extract the route-shape primitives into a Routing leaf module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/816\n* Rewrite the catalog listing copy by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/819\n* Add a supported-providers matrix and an honest comparison table by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/820\n* Require docs-impact tracking for every change by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/824\n* Publish the governance, support, CRA, privacy and remediation policy set by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/825\n* Enforce bracketed issue references in every commit subject by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/836\n* Enable nullable reference types across the leaf modules by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/838\n* Enable nullable reference types across Provider, Linking and Session by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/839\n* Link the maturity map from README and SECURITY by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/840\n* Enable nullable reference types across the Shared module by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/841\n* Pin the persisted SSO AuthenticationProviderId, decoupled from the controller type by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/842\n* Extract the Http boundary module and lock the flat Api kernel empty by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/843\n* Constrain the Flows and Shared module import lists in the DAG test by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/845\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.2.1-beta.7...4.3.0-beta.8", "checksum": "00b08b1463e211f5cbe8f0cfef444e88", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.3.0-beta.8/sso-authentication_4.3.0.8.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-20T06:57:18Z", "version": "4.3.0.8" }, { "changelog": "Jellyfin 10.11 beta 4.2.1-beta (plugin version 4.2.1.7).\nInstall via the beta repository URL:\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Show link success instead of \"Login failed\" after account linking (#614) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/639\n* Fix .NET CI startup_failure on 4.3 (reusable build.yml permissions) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/644\n* Document the reusable build.yml caller-permission contract by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/647\n* Record single-logout design constraints (#154) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/648\n* Document the review-gate coverage after external-reviewer removal (#101) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/649\n* Derive the DORA four keys from git/GitHub (#175) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/650\n* Conformance test: build-*.yaml artifacts equal the per-TFM publish closure (#608) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/651\n* Document and drill the release rollback path (#151) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/652\n* Threat-model SSO-only login before building (Refs #165) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/653\n* Add the JF12 stable publish leg (#607) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/654\n* Add the AI-delivery-pipeline threat model; classify agent-config as sensitive (#152) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/656\n* Consolidate the milestone branches (P4/P5/P5b/P6 work) onto main by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/657\n* Share the publish-manifest-release concurrency group (#655) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/658\n* Formalize the daily beta as the release canary soak stage (#172) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/659\n* OpenSSF Best Practices criteria mapping + badge readiness (#403) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/660\n* Advisory deterministic PR-hygiene checks (#171) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/661\n* Full RBAC mapping: SSO claims -> PermissionKind (default-deny) (#164) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/662\n* Move design/process/architecture docs to the wiki; keep only required files by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/663\n* Make the PR-hygiene size check advisory (WARN, never FAIL) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/664\n* Widen unicode-guard to all branches; tidy publish-pipeline config by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/691\n* Correct stale version references in README and CHANGELOG by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/692\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.2.1-stable...4.2.1-beta.7", "checksum": "ee0da7d62e9f40a559b3331a89e67982", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.2.1-beta.7/sso-authentication_4.2.1.7.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-19T06:39:56Z", "version": "4.2.1.7" }, { "changelog": "## What's Changed\n* Fix .NET CI startup_failure on main (reusable build.yml permissions) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/642\n* Bump github/codeql-action to v4.37.0 (consolidates #611/#612/#613) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/645\n* Release 4.2.1: authz null-context hardening + CI fix by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/646\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.2.0-stable...4.2.1-stable", "checksum": "b25d638b47ba02903a6699924c5256df", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.2.1-stable/sso-authentication_4.2.1.0.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T23:56:24Z", "version": "4.2.1" }, { "changelog": "## What's Changed\n* Forward-merge main into 4.2 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/562\n* Widen SourceFilesDeclaring to match record struct and struct declarations by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/558\n* Add SAML service-provider metadata endpoint by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/567\n* Forward-merge main into 4.2 (post-4.1.0.0 fixes) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/572\n* Add a SAML SP signing-key rollover (part 1 of #491) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/573\n* Forward-merge main into 4.2 (codeql.yml advanced setup) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/576\n* Add an admin Test-connection action per provider by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/577\n* Add admin config export/import (#161) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/581\n* Forward-merge main into 4.2 (README banner) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/580\n* Accept a SAML response signed by an optional secondary IdP certificate (completes #491) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/582\n* Forward-merge main into 4.2 (CA1873 log hygiene + Alpha docs) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/588\n* Forward-merge main into 4.2 (the 4.1.1.0 line + release channels) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/595\n* Multi-target net9.0/net10.0 for the 10.11 and 12.0 lines (#135) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/596\n* Forward-merge main into 4.2 (3-part versions + release naming) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/598\n* Evaluate SAML assertion roles once per login (#479) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/599\n* Scoped Stryker.NET mutation testing for the SAML/OIDC core (#169) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/600\n* Weekly SharpFuzz job over the SAML parse surface (#174) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/601\n* Forward-merge main into 4.2, set 4.2 to its 4.2.0 feature target by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/603\n* Collapse SamlChallenge relayState init to a ternary (#456) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/604\n* Jellyfin 12.0 (5.0) beta publish leg + two-channel manifest model (#135) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/605\n* Attest SLSA build provenance for the release plugin zip (#147) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/609\n* Drop the deprecated assertion-embedded SAML/Auth path (#528) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/610\n* Document the whole-object-replace contract on provider config (S6964, #196) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/615\n* Decompose ConvertSigningKeys to cut OIDC id_token validator complexity (S3776, #196) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/616\n* Accept-with-reason analyzer dispositions in .editorconfig (#104 Unit 0) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/617\n* Make WebResponse string ops culture-invariant (#104 Unit 1) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/618\n* Adopt System.Threading.Lock in three lock sites (#104 Unit 3) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/619\n* Add paramName to ArgumentException throws (#104 Unit 2, MA0015) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/620\n* Correct the stale target-direction section in ARCHITECTURE.md (#318) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/621\n* Test the write-only secret converter redaction contract (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/622\n* Test the AuthorizeStateBinding anti-forgery cookie (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/623\n* Test the SsoRateLimitGate 429 + fail-open invariant (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/624\n* Test the admin-or-self authorization helper (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/625\n* Anchor JF12 beta releases to the built 4.2 commit (#627) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/628\n* Test ProviderConfigValidator reject paths (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/629\n* Test SSOViewsController GetView (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/630\n* Test FlowResponses shaping helpers (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/631\n* Publish JF12 beta daily, not per 4.2 merge (#632) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/633\n* Test config XML lifecycle round-trip (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/635\n* Test [Authorize]-policy enforcement end-to-end (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/636\n* Test fake-IdP OIDC challenge->callback->auth round-trip (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/637\n* Record the manual release-QA checklist (#192) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/638\n* Release 4.2.0: merge the 4.2 feature line into main by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/640\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.6...4.2.0-stable", "checksum": "74a99a85afc026a85af3fe92194213ac", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.2.0-stable/sso-authentication_4.2.0.0.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T23:13:45Z", "version": "4.2.0" }, { "changelog": "Jellyfin 10.11 beta 4.1.2-beta (plugin version 4.1.2.6).\nInstall via the beta repository URL:\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Add daily beta scheduler; stop per-push betas (#632) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/634\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.5...4.1.2-beta.6", "checksum": "49079645241d822c71a79f60eaf557e7", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.1.2-beta.6/sso-authentication_4.1.2.6.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T22:38:05Z", "version": "4.1.2.6" }, { "changelog": "Jellyfin 10.11 beta 4.1.2-beta (plugin version 4.1.2.5).\nInstall via the beta repository URL:\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* publish-beta: shared publish-manifest-beta concurrency group by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/606\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.2-beta.4...4.1.2-beta.5", "checksum": "5f7e3ff51a1062d1078edcdc0e5fa39a", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.1.2-beta.5/sso-authentication_4.1.2.5.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T20:41:43Z", "version": "4.1.2.5" }, { "changelog": "Jellyfin 10.11 beta 4.1.2-beta (plugin version 4.1.2.4).\nInstall via the beta repository URL:\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Beta tracks the next release target (4.1.2-beta), maintainer-set by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/602\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/4.1.1-beta.3...4.1.2-beta.4", "checksum": "aaf38de395e1d79ad449d9cecf15514f", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.1.2-beta.4/sso-authentication_4.1.2.4.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T19:48:59Z", "version": "4.1.2.4" }, { "changelog": "Jellyfin 10.11 beta 4.1.1-beta (plugin version 4.1.1.3).\nInstall via the beta repository URL:\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\n\n\n## What's Changed\n* Three-part versions + X.Y.Z- release names + auto release notes by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/597\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/beta-4.1.1.2...4.1.1-beta.3", "checksum": "a7b7e18dde83445b7118be3079c518ee", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.1.1-beta.3/sso-authentication_4.1.1.3.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T18:50:33Z", "version": "4.1.1.3" }, { "changelog": "Jellyfin 10.11 beta build (4.1.1.2).\r\nInstall via the beta repository URL:\r\nhttps://raw.githubusercontent.com/iderex/jellyfin-plugin-sso/manifest-beta/manifest.json\r\n\r\n## What's Changed\r\n* Surface failed loads and unlink deletes on the linking page by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/565\r\n* Surface failed GetNames loads on the linking page by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/570\r\n* Decompose the ~210-line ResolveOrCreateAsync account-resolution method by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/568\r\n* Record the challenge NewPath through MutateConfiguration by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/571\r\n* Add advanced CodeQL workflow covering main and 4.2 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/575\r\n* Use the new security-team artwork as the README banner by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/579\r\n* Add SharpFuzz harness prototype for the login-path parse surface by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/583\r\n* Guard computed logging arguments behind IsEnabled (net10 CA1873 prep) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/586\r\n* Advance to Alpha and document the plugin-catalog install path by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/585\r\n* Pin OidcClient to 6.x to restore loading on Jellyfin 10.11 (4.1.1.0) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/591\r\n* Release channels: JF10.11 beta manifest + JF10.12 placeholders (#592) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/593\r\n* Fix beta publish under immutable releases (draft + unique tag) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/594\r\n\r\n\r\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/v4.1.0.0...beta-4.1.1.2", "checksum": "9e522ee7dde9fdc1917ac22f54eb9b63", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/beta-4.1.1.2/sso-authentication_4.1.1.2.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T17:48:22Z", "version": "4.1.1.2" }, { "changelog": "## What's Changed\n* Three-part versions + X.Y.Z- release names + auto release notes by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/597\n\n\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/beta-4.1.1.2...4.1.1-stable", "checksum": "24912d4038c21b72efa7472d9d3cec2b", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/4.1.1-stable/sso-authentication_4.1.1.0.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T19:06:10Z", "version": "4.1.1" }, { "changelog": "## What's Changed\r\n* Adopt secure development process and repository hygiene by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/3\r\n* Bump softprops/action-gh-release from 50195ba7f6f93d1ac97ba8332a178e008ad176aa to 132dbbba49e22bd4837f09b46d32a8edaf6baa58 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/11\r\n* Bump Kevinjil/jellyfin-plugin-repo-action from 0.4.0 to 0.4.3 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/4\r\n* Bump creyD/prettier_action from 4.3 to 4.6 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/5\r\n* Bump actions/checkout from 2 to 7 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/6\r\n* Bump actions/setup-dotnet from 1 to 5 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/7\r\n* Bump actions/download-artifact from 5.0.0 to 8.0.1 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/8\r\n* Bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/9\r\n* Bump fjogeleit/yaml-update-action from 0.10.0 to 0.17.0 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/10\r\n* Bump Duende.IdentityModel.OidcClient from 6.0.1 to 7.1.0 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/12\r\n* Bump Jellyfin.Model from 10.11.0 to 10.11.11 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/14\r\n* Bump System.Security.Cryptography.Xml from 9.0.13 to 10.0.9 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/16\r\n* Bump Newtonsoft.Json from 13.0.3 to 13.0.4 by @dependabot[bot] in https://github.com/iderex/jellyfin-plugin-sso/pull/15\r\n* Add xUnit test foundation with SAML validation regression tests by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/18\r\n* Remove unconfigured Black Duck security scan workflow by @iderex with @Copilot in https://github.com/iderex/jellyfin-plugin-sso/pull/19\r\n* Fix thread-unsafe OpenID state store by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/21\r\n* Remove unconfigured APIsec scan workflow by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/23\r\n* Harden SAML assertion time validation (fail-closed) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/25\r\n* Bind SSO logins to existing accounts fail-closed by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/27\r\n* Constrain server-side avatar fetch to public http(s) targets by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/29\r\n* Validate SAML assertion AudienceRestriction by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/31\r\n* Enforce one-time use of SAML assertions (replay protection) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/33\r\n* Harden the avatar fetch from Copilot review feedback by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/35\r\n* Polish SAML validation and fix relayState log forging by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/37\r\n* Add least-privilege permissions to CI workflows by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/39\r\n* Pin third-party GitHub Actions to commit SHAs by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/41\r\n* Tidy the account-link switch and exception (Copilot review) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/43\r\n* Harden the SAML test factory and OpenID state add (Copilot review) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/45\r\n* Rework the README into a truthful landing page by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/47\r\n* Link the wiki from the README by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/48\r\n* Refine the README AI note and name the sibling project by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/50\r\n* Serialize plugin-configuration read-modify-writes by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/52\r\n* Add a vulnerable-dependency CI gate by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/54\r\n* Enforce the SAML login role allow-list at the session-minting endpoint by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/55\r\n* Bind OpenID authorize state to its provider and make it single-use by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/56\r\n* Verify Jellyfin compatibility in CI (ABI consistency + packaging) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/58\r\n* Require modern signature algorithms in SAML validation by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/59\r\n* Add Copilot custom instructions for code review by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/62\r\n* Resolve SonarCloud findings across web assets and the compat script by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/64\r\n* Remove stray comment token breaking the checkbox-wrapper rule by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/67\r\n* Use optional chaining in the server-response filter by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/65\r\n* Scope SonarCloud analysis to source, excluding img assets by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/71\r\n* Build the account-linking DOM without HTML interpolation by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/68\r\n* Document the mandatory two-reviewer PR process in CODEOWNERS by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/72\r\n* Run SonarCloud analysis in CI instead of Automatic Analysis by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/73\r\n* Import test coverage into the SonarCloud analysis by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/74\r\n* Fix delete-button contrast and drop dead filter-bubble CSS by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/75\r\n* Fail closed on a missing user and namespace SerializableDictionary by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/77\r\n* Hoist and time-box the role-claim split regex by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/78\r\n* Encode the auth-completion data value as a JS string literal by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/80\r\n* Build auth-page URLs from JSON-encoded constants, not raw interpolation by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/81\r\n* Remove unused injected dependencies from SSOViewsController by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/82\r\n* Tidy pure helpers: LINQ filters, member order, argument guards by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/83\r\n* Tidy Saml.cs: static helper, LINQ audience check, dead comments, guard by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/84\r\n* Split the avatar SSRF range checks and guard Generator's baseUrl by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/85\r\n* Extract the OIDC role-claim parsing into a tested pure helper by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/86\r\n* Mechanical tidy of SSOController (behavior-neutral) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/87\r\n* Use structured logging templates in two controller log calls by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/88\r\n* Extract the OID role-to-privilege mapping into a tested pure helper by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/90\r\n* Extract the SAML role-to-privilege mapping into a tested pure helper by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/91\r\n* Use Length instead of Any() for the role-claim segment guard by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/92\r\n* Group Authenticate's parameters into a SessionParameters object by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/93\r\n* Extract OID authorize-state derivation into a pure builder by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/94\r\n* Extract SAML authorize-state derivation into a pure builder by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/96\r\n* Deduplicate the OIDC client construction by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/97\r\n* Drop the Copilot review step from the CODEOWNERS process note by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/100\r\n* Add CodeRabbit review configuration by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/102\r\n* Add a dependency-review PR gate by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/103\r\n* Enable the .NET security analyzers as a standing in-build reviewer by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/107\r\n* Lint the PR merge commit instead of checking out head_ref by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/108\r\n* Use logical OR in the SAML Live TV grant merge by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/109\r\n* Split the OIDC authorize-state derivation into focused helpers by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/110\r\n* Bump setup-java and cache actions in the SonarCloud workflow by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/111\r\n* Fail closed when a login resolves no identity by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/112\r\n* Deduplicate the denial message and drop null-guards the belt made dead by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/113\r\n* Rebuild the OID callback redirect_uri from the callback's own route by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/114\r\n* Remove the vestigial F# Lib project by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/116\r\n* Harden the NuGet supply chain: source mapping, lock files, locked-mode CI by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/118\r\n* Prohibit DTD processing when parsing the SAML response (XXE / DoS) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/121\r\n* Set defensive response headers on the rendered auth page by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/124\r\n* Add FsCheck property tests over the pure login-decision helpers by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/127\r\n* Make string comparisons explicitly ordinal on the auth path by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/130\r\n* Add a structured SSO audit log by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/132\r\n* Add a pre-alpha production-use warning to the top of the README by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/180\r\n* Fix CONTRIBUTING.md drift and document XXE/state-replay hardening by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/183\r\n* Validate the OpenID Connect id_token by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/182\r\n* Reflect the id_token validation in the README and fix a config key typo by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/184\r\n* Key the OpenID account link on the stable sub claim by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/185\r\n* Bind SAML responses to this SP: Recipient and InResponseTo by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/187\r\n* Preserve server-managed canonical links across config saves by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/188\r\n* Make SSO account adoption atomic by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/190\r\n* Add opt-in per-client rate limiting to the anonymous SSO endpoints by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/193\r\n* Make the OpenID client secret write-only in JSON responses by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/197\r\n* Harden SAML signature processing against XML-signature-wrapping by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/198\r\n* Surface and audit-log the insecure OpenID discovery toggles by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/200\r\n* Record the client IP for SSO logins in Jellyfin's activity log by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/201\r\n* Pin the OpenID state single-use / invalidate-on-consumption invariant by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/202\r\n* Add a canonical external base-URL override by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/203\r\n* Reject malformed SAML callback input with a clean 400, not a 500 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/205\r\n* Reject a non-form POST to the SAML ACS with a clean 400 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/207\r\n* Reject an unloadable SAML certificate instead of 500-ing every callback by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/208\r\n* Validate the RFC 9207 authorization-response issuer by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/209\r\n* Harden and speed up the CI/CD workflows by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/223\r\n* Harden the SSO login-completion path (fail-closed robustness) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/224\r\n* Add a 7-day Dependabot cooldown for nuget and github-actions by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/225\r\n* Escape media-folder Name/Id in the config-page folder list by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/227\r\n* Clarify the ExtractRoles fail-closed comment for mixed role arrays by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/228\r\n* Restrict avatar content types to a raster allow-list by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/229\r\n* Consume the SAML replay cache in the account-linking callback by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/230\r\n* Make Unregister actually revoke SSO access, persist, and null-guard by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/231\r\n* Check PKCE (S256) support at OpenID discovery by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/233\r\n* Add a CI gate that rejects Trojan Source Unicode by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/250\r\n* Cap the SAML response size before base64 decode and DOM parse by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/254\r\n* Cap and throttle the OIDC authorize-state store by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/255\r\n* Take the config lock for login-path provider-dictionary reads by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/256\r\n* Remove dead upstream AspNetSaml surface from Saml.cs by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/257\r\n* Serve embedded view assets with an ETag for 304 revalidation by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/258\r\n* Dead-code sweep: unused constructors, redundant defaults, debug logging by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/259\r\n* Package the SAML crypto runtime DLLs (fix packaged SAML login) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/260\r\n* Migrate the injected login JS off the deprecated X-Emby-Authorization header by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/261\r\n* Add a zizmor CI gate over the GitHub Actions workflows by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/262\r\n* Add a nonce-based Content-Security-Policy to the auth page by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/264\r\n* Skip zizmor SARIF upload on fork and Dependabot PRs by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/265\r\n* Reset SSO config toggles when switching providers by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/266\r\n* Expand the public AI-and-contributions note by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/268\r\n* Make the CanonicalLinks getter self-healing by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/269\r\n* Replace KeyNotFoundException control flow in the provider lookup with a null check by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/270\r\n* Extract GetRequestBase's URL derivation into CanonicalBaseUrl.Resolve by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/271\r\n* Elide the default port against the effective scheme, not the request scheme by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/273\r\n* Point the plugin manifest and docs at this repository by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/274\r\n* Add explicit assertions to the does-not-throw tests by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/275\r\n* Document the real build, test, and branch flow in CONTRIBUTING by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/276\r\n* Verify the plugin builds against the declared targetAbi floor in CI by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/277\r\n* Record the enabled repository security controls in SECURITY.md by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/278\r\n* Add an in-process SSOController test harness and first endpoint tests by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/279\r\n* Cover disabled providers, state validation, and the read endpoints by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/280\r\n* Cover the provider-delete endpoints and the rate-limit 429 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/281\r\n* Cover the provider-add endpoints and canonical-link preservation by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/282\r\n* Cover the enabled SAML challenge, the Unregister guard, and the provider lists by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/283\r\n* Introduce the In-Development → Full Release maturity ladder in the docs by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/285\r\n* Cover the Unregister happy path and the canonical-link endpoints by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/286\r\n* Cover the canonical-link add/delete outcomes by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/287\r\n* Cover the SAML challenge linking, solicited-only, and rate-limit branches by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/288\r\n* Cover the OpenID challenge PKCE-discovery fail-closed gate (#141) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/290\r\n* Point config page help links at this repo's wiki by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/293\r\n* Point config page roadmap link at this project's board by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/295\r\n* Make the OpenID authorize-state store test-resettable by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/292\r\n* Add a Login Flow wiki page and link it from the README by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/296\r\n* Cover the OpenID auth callback (OidAuth) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/299\r\n* Correct misleading config doc-comments for NewPath and FolderRoleMap by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/300\r\n* Cover the SAML auth callback (SamlAuth) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/301\r\n* Dedupe the challenge NewPath logic and correct misleading doc-comments by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/302\r\n* Cover the canonical-link add success paths and per-user link queries by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/304\r\n* Cover the SAML assertion-consumer callback (SamlPost) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/306\r\n* Deduplicate device-name logic onto WebResponse.cs by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/308\r\n* Add a bounded throttle-engaged observability signal to the rate limiter by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/307\r\n* Consolidate shared SamlConfig/OidConfig members into ProviderConfigBase by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/309\r\n* Add OpenSSF Scorecard supply-chain self-audit workflow by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/311\r\n* Add rel=\"noopener noreferrer\" to the config page Help link by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/314\r\n* Cover the OpenID redirect callback token-exchange path (OidPost) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/313\r\n* Pin the 2025-2026 SAML attack shapes with characterization tests by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/312\r\n* Retarget linking page help links off archived 9p4 upstream by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/315\r\n* Key IPv4-in-IPv6 transition rate-limit sources on the embedded IPv4 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/317\r\n* Add Opengrep gate for greppable repo invariants by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/316\r\n* Order TryExtractEmbeddedIPv4 among the internal members by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/321\r\n* Add architecture-conformance fitness tests as a mandatory per-PR check by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/322\r\n* Tighten the architecture-conformance rules (close the #322 review gaps) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/323\r\n* Rename the SAML core types and extract the controller data records (#318 step 1a) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/324\r\n* Extract the provider-scoped one-time-use key into ProviderScopedKey (#318 step 2) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/325\r\n* Add rel=\"noopener noreferrer\" to the linking.html Help button by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/330\r\n* List Scorecard and Opengrep in the security policy's repository controls by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/332\r\n* Add a CRLF/pretty-printed signed-SAML interop regression test by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/333\r\n* Extract the once-per-interval throttle into IntervalGate by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/331\r\n* Adopt IntervalGate at the three remaining throttle sites by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/335\r\n* Extract the SSO URL construction into SsoUrlBuilder by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/339\r\n* Correct the Keycloak SAML assertion URL in providers.md by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/340\r\n* Consolidate the OpenID authorize-state store into OidcStateStore by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/342\r\n* Reject linking through a disabled provider by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/345\r\n* Introduce LoginOutcome and LoginStatusMapper by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/347\r\n* Make client-caused login rejections 4xx, not 500 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/349\r\n* Extract the config boundary into ProviderConfigStore by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/348\r\n* State that development is currently stopped in the README by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/351\r\n* Semi-halt notice, maintainership handover, iderex-only merge gate, and drop the public AI claim by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/352\r\n* Extract the login-path account linking into CanonicalLinkService by @TheRealStroopwafel in https://github.com/iderex/jellyfin-plugin-sso/pull/353\r\n* State plainly that review is amongst AI-driven #decided against it and revert by @TheRealStroopwafel in https://github.com/iderex/jellyfin-plugin-sso/pull/355\r\n* Remove the AI note from the public docs by @TheRealStroopwafel in https://github.com/iderex/jellyfin-plugin-sso/pull/357\r\n* List the full maintainer team in CODEOWNERS by @TheRealStroopwafel in https://github.com/iderex/jellyfin-plugin-sso/pull/356\r\n* Reject URI-reserved characters in new provider names by @rekamer in https://github.com/iderex/jellyfin-plugin-sso/pull/359\r\n* Gate the legacy-link migration behind AllowExistingAccountLink by @shippingToken in https://github.com/iderex/jellyfin-plugin-sso/pull/358\r\n* Move the manual link/unlink admin surface into CanonicalLinkService by @TheRealStroopwafel in https://github.com/iderex/jellyfin-plugin-sso/pull/373\r\n* Extract the SSRF-safe avatar fetch into AvatarService by @TheRealStroopwafel in https://github.com/iderex/jellyfin-plugin-sso/pull/375\r\n* Reject control characters in new provider names by @rekamer in https://github.com/iderex/jellyfin-plugin-sso/pull/376\r\n* Route server-managed re-injection through ServerManagedFields.Preserve by @shippingToken in https://github.com/iderex/jellyfin-plugin-sso/pull/387\r\n* Centralize outbound HTTP client creation in SsoHttp by @TheRealStroopwafel in https://github.com/iderex/jellyfin-plugin-sso/pull/379\r\n* Extract session minting into SessionMinter by @rekamer in https://github.com/iderex/jellyfin-plugin-sso/pull/390\r\n* Write the avatar before touching the user's profile-image record by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/399\r\n* Rework the README status notes by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/398\r\n* Reject a provider disabled mid-flight on every grant path by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/404\r\n* Make the SonarCloud job the required gate instead of the app status by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/405\r\n* Normalize null OidScopes so the challenge does not 500 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/408\r\n* Reject a null provider body at the Add endpoints by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/409\r\n* Add a controller socket/DNS tripwire to the conformance rules by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/406\r\n* Match the challenge route segment exactly, not as a substring by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/410\r\n* Persist the default provider in the single session-mint write by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/413\r\n* Bind the OpenID authorize state to the initiating browser by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/416\r\n* Bind the SP-initiated SAML login to the initiating browser by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/417\r\n* Make the avatar fetch path unit-testable behind a handler seam by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/418\r\n* Store the avatar with a real dotted file extension by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/419\r\n* Reuse the resolved subject for the OpenID sub fallback by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/420\r\n* Flatten OidPost's provider guard and drop dead link-helper attributes by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/421\r\n* Define the SAML algorithm allow-list predicate once by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/422\r\n* Fold the SAML XML loaders into SamlResponse construction by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/423\r\n* Collapse the per-mode twin blocks over ProviderConfigBase by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/424\r\n* Compact the helpers: record struct, dead guards, constant parameter by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/425\r\n* Remove the CodeRabbit and Copilot review integrations by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/426\r\n* Bound the in-flight login state stores per client by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/427\r\n* Unify the two role-privilege mappers behind ProviderConfigBase by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/428\r\n* Strip the dead browser-detection code from the auth page script by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/429\r\n* Document the admin-UI dev loop and the vendored view-asset provenance by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/430\r\n* Make the provider form's save contract explicit and drop the dead sso-json path by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/431\r\n* Drop blank scope elements in BuildScopeString by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/433\r\n* Require the legacy link's target to still bear the presented name before following it by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/435\r\n* Anchor OidcCallbackPath.RedirectSegment to the route suffix by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/434\r\n* Reuse the challenge's validated discovery metadata at the OpenID callback by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/437\r\n* Characterize the OIDC callback against COAT and session fixation by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/438\r\n* Re-check the identity link before minting an SSO session by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/439\r\n* Tighten SAML assertion conformance: signatures, audience, bearer by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/441\r\n* Update ChallengePath cross-reference now that RedirectSegment is suffix-anchored by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/442\r\n* Harden the controller link-map conformance scan against split and rename by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/443\r\n* Serialize the per-user avatar store against concurrent logins by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/445\r\n* Reject unsafe usernames when building the avatar profile path by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/459\r\n* Harden the OIDC RFC 9207 authorization-response issuer check by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/446\r\n* Document the SAML audience validation options in providers.md by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/454\r\n* Add a positive-control sentinel to the socket/DNS conformance scan by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/462\r\n* Remove SonarCloud from the repo; confirm CodeRabbit/Copilot are gone by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/463\r\n* Gate account adoption on admin status and a verified claim (#218) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/464\r\n* Harden IntervalGate against stale-sample re-admission by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/465\r\n* Collapse repeated PluginPageInfo construction in SSOPlugin by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/466\r\n* Revoke active tokens when unregistering a user by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/467\r\n* Bound SamlReplayCache with a hard cap and throttled prune by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/469\r\n* Add an AI-assisted, human-owned disclosure to the README by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/472\r\n* Add an in-repo architecture / login-flow map by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/475\r\n* Compact admin-UI JS in linking.js and config.js by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/476\r\n* Fold legacy-link re-key into one authoritative migration transaction by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/477\r\n* Trim redundant per-login work in the avatar fetch by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/478\r\n* Document remaining OpenID config keys and multi-restriction SAML audience semantics by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/481\r\n* Enable TreatWarningsAsErrors as a project default by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/482\r\n* Surface AllowExistingAccountLink in the admin provider form by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/484\r\n* Swap the OpenID authorize state atomically instead of promoting it in place by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/485\r\n* Bump NSubstitute to 6.0.0 by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/487\r\n* Surface RequireVerifiedEmailForAdoption in the admin provider form by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/488\r\n* Correct stale config.xml-only claim for two adoption flags by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/490\r\n* Sign outgoing SAML AuthnRequests (HTTP-Redirect binding) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/492\r\n* Make the null-config-maps preservation contract explicit (S2699) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/494\r\n* Introduce VerifiedIdentity as the session-mint keystone by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/495\r\n* Extract the shared login-completion tail into a flow service by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/497\r\n* Extract the OpenID discovery-facts cache into OidcDiscoveryCache by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/498\r\n* Route rate-limit rejection through LoginOutcome.Throttled by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/499\r\n* Extract the OpenID login flow into OidcLoginService by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/500\r\n* Extract the SAML login flow into SamlLoginService by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/501\r\n* Move the shared rate-limit gate off SSOController into the Shared tier by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/503\r\n* Parse the oid/saml mode token once at the controller boundary by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/504\r\n* Sweep contributor-clarity traps: callback naming, dead accessor, IP-classifier home, asset casing by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/506\r\n* Split OidcIdTokenValidator into named validation sub-checks by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/512\r\n* Throttle the pending-legacy-link warning through a shared IntervalGate by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/513\r\n* Rate-limit the authenticated link/unlink admin endpoints by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/514\r\n* Support ECDSA service-provider signing keys for outgoing SAML requests by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/515\r\n* Name ECDSA in the two SP signing-key rejection messages by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/519\r\n* Rate-limit the Unregister admin endpoint by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/520\r\n* Extract a dedicated SAML assertion-validator type by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/521\r\n* Add opt-in verified-email gate for OpenID logins by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/522\r\n* Derive a real device name for the SSO linking view by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/523\r\n* Add Kanidm to the tested-providers index in providers.md by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/511\r\n* Surface RequireVerifiedEmailForLogin in the admin provider form by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/525\r\n* Address zizmor pedantic workflow code-smells by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/527\r\n* Replace the SAML assertion browser round-trip with a one-time outcome token by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/531\r\n* Force-refresh the SSO avatar when the on-disk file is missing by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/530\r\n* Stop offering disabled providers on the linking page and surface link rejections by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/535\r\n* Correct stale config.xml-only claim for RequireVerifiedEmailForLogin by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/533\r\n* Surface a throttled cap-refusal capacity warning from SamlReplayCache by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/537\r\n* Single-source the shared authorize-state privilege merge by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/545\r\n* Share the route-suffix reader between ChallengePath and OidcCallbackPath by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/543\r\n* Bound the avatar store-lock acquire wait with a timeout by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/544\r\n* Revoke tokens on last-link unlink; document per-provider disable non-revoke by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/546\r\n* Document anonymous-by-design posture of the GetNames endpoints by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/547\r\n* Source OIDC discovery facts from the login's own discovery response by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/548\r\n* Generalize the shared 429 body wording by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/551\r\n* Shorten the avatar store-lock acquire timeout to 3s by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/552\r\n* Encrypt provider secrets at rest (AES-256-GCM envelope, transparent migration) by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/549\r\n* Harden SecretStore key handling: orphan-prevention and atomic 0600 temp key by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/553\r\n* Bind OpenID canonical links to the discovered issuer by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/554\r\n* Prepare the 4.1.0.0 release by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/555\r\n* Publish the release from a version-tag push by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/557\r\n* Make EnabledProviderNames predicate null-safe by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/559\r\n* Widen dotnet/prettier pull_request triggers to all branches by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/561\r\n* Reserve the SAML outcome-store slot before the replay consume by @iderex in https://github.com/iderex/jellyfin-plugin-sso/pull/563\r\n\r\n## New Contributors\r\n* @dependabot[bot] made their first contribution in https://github.com/iderex/jellyfin-plugin-sso/pull/11\r\n* @iderex with @Copilot made their first contribution in https://github.com/iderex/jellyfin-plugin-sso/pull/19\r\n* @TheRealStroopwafel made their first contribution in https://github.com/iderex/jellyfin-plugin-sso/pull/353\r\n* @rekamer made their first contribution in https://github.com/iderex/jellyfin-plugin-sso/pull/359\r\n* @shippingToken made their first contribution in https://github.com/iderex/jellyfin-plugin-sso/pull/358\r\n\r\n**Full Changelog**: https://github.com/iderex/jellyfin-plugin-sso/compare/v4.0.0.4...v4.1.0.0", "checksum": "05481d0187e1036ce5031ca77794121c", "sourceUrl": "https://github.com/iderex/jellyfin-plugin-sso/releases/download/v4.1.0.0/sso-authentication_4.1.0.0.zip", "targetAbi": "10.11.0.0", "timestamp": "2026-07-18T13:39:34Z", "version": "4.1.0.0" } ] } ]